Splunk Data preview - Timestamp in milliseconds, Regex problems -


Trying to parse the timestamp in milliseconds with this regx:

\ d {7} /

Why is not any idea working?

  9281736: 1003 tx in COUNT: 01 04 00 71 00 02 21 d0 ... q ..! Rx: 01 04 04 00 08 AA 287CF8 ...... (| 9282136: COUNT in 1003 Tx: 01 04 00C9 002A1F5 ........ Rx: 01 04 04 00 08 00 00 7a 46 ....... zF 9282536: 1003 tx in COUNT: 01 04 01 2 d 00 02 E3E ... -... ... RX: 01 04 04 00 00 FF FF FA 34 ... ..... 498 9 36: COUNT 1003 Tx: 01 04 01 F 05 00 02 60 05 ...... `Rx: 01 04 04 00 23 00 00 0A4E  

I preview and receive timestamp error messages with "unsorted data" - "Unable to parse timestamp." File modem Default for ".

I think Regex to \ d {7} Should be, / \ d {7} . Note the slash!


Comments